Impact
The Fuelthemes Werkstatt theme in WordPress versions up to 4.8.3 contains a PHP Object Injection vulnerability (CWE‑502). Attackers who can submit serialized data to the theme are able to trigger an unserialize operation that executes arbitrary PHP code. This flaw can compromise the confidentiality, integrity and availability of the site, as the attacker could gain full control of the affected system.
Affected Systems
All WordPress installations that include the Fuelthemes Werkstatt theme version 4.8.3 or any earlier release are affected. If the theme is still present on a live site, the vulnerability remains exploitable until the theme is removed or upgraded.
Risk and Exploitability
The CVSS score of 8.8 classifies this defect as high severity. The EPSS score of <1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. The likely vector is remote; an attacker can trigger the vulnerability by sending crafted HTTP requests containing malicious serialized payloads to the theme, for example via contributor or custom fields that the theme deserializes.
OpenCVE Enrichment